Categories
Knowledge Support Support exacqVision Server Categories Products

Axis analytic event linking items become invalid from add/remove analytic application in camera.

Description

This issue was discovered when we implemented additional shock analytic event support for the Axis plugin. The event linking items were not assigned an unique id but rely on the next item in the list. So if additional analytic event applications are loaded, the initial ID assigned to the analytic event linking item would be invalid depends on the order it is loaded. The fix would be to assign an unique id to each analytic event supported by Axis so any new analytic event added to the system would not invalid or replace the existing ones.

<br>

Version Introduced

r88921 (7.3.20.88942/7.4.0.89235)

<br>

Platform

All

<br>

Steps to reproduce

  1. load cross line application from the camera page(P1364 AC-CC-8E-02-A8-BB was used for this example)
  2. connect to server and add cross line analytic in event linking list.
  3. load VMD3 application in the camera.
  4. disable/enable the axis camera from server.
  5. this Axis should have both cross line and VMD3 in the analytic event linking list.

<br>

Expected result

the existing cross line analytic event should stay valid.

Actual result

the existing cross line analytic event is invalid.

<br>

Work Around

manually replace the invalid event linking item

<br>

Version Fixed

none

<br>

Keywords

Axis Analytic

Categories
Knowledge Support Support Categories exacqVision Webservice Products

Days recorded displayed is incorrect

Description

The days recorded value in the Systems page is incorrect. It is displaying the number of days since the Unix epoch (6/1/1970).

<br>

Version Introduced

7.9.24

<br>

Platform

Web Service / All

<br>

Steps to reproduce

  1. Open the web client and log into a server.
  2. View the Systems Page

<br>

Expected result

The “Days Recorded” field matches the client.

<br>

Actual result

The “Days Recorded” field is the number of days since the epoch.

<br>

Work Around

Downgrade to 7.8.

Categories
Knowledge Support Support Categories exacqVision Webservice Products

AVI exports fail

Description

In the web service, exports in AVI format fail. The export is started, but no progress is ever shown and the export never completes.

<br>

Version Introduced

7.7.24

<br>

Platform

Web Service/Windows

<br>

Steps to reproduce

On the search page, create an export, selecting the AVI format.

Expected result

The export progresses as expected.

<br>

Actual result

The export hangs on starting, with no progress ever displaying.

<br>

Work Around

  • * Export video to another format (PS, EXE)
  • * Remove the FFMPEG libraries

1. Remove the following files from C:\Program Files (x86)\exacqVision\WebService\bin\:


avcodec-56.dll
avfilter-5.dll
avformat-56.dll
avutil-54.dll
swresample-1.dll
swscale-3.dll

2. Restart the web service.

  • * Downgrade to 7.6.

<br>

Version Fixed

8.1.8

Categories
Knowledge Support Support Categories exacqVision Webservice Products

Web service cannot connect to multiple servers at the same address

Description

If web service with more than one server at the same address, but different ports, those servers are not treated independently. When accessing these servers through the web service, only the first will handle requests.

<br>

Version Introduced

7.5.32

<br>

Platform

All

<br>

Steps to reproduce

  1. Configure two servers at the same IP with different ports (e.g. using a router).
  2. Add those servers to the web service.

Expected result

Both servers are handled as separate entities.

<br>

Actual result

The servers are handled incorrectly in the web service, not always using the correct server.

<br>

Work Around

Set up separate DNS entries for each server (i.e. give a unique address for each).

<br>

Version Fixed

none

Categories
Knowledge Support Support Categories exacqVision Webservice Products

Exporting video logs out of all connected servers

Description

Exporting video logs out of all connected servers.

<br>

Version Introduced

8.1.5

<br>

Platform

Web Service

<br>

Steps to reproduce

  1. Create a search
  2. Start a video export
  3. When the export is complete, click on an exported file to download.

<br>

Expected result

The logged in servers are not logged out.

<br>

Actual result

The servers are logged out.

<br>

Work Around

Refresh the page to log back into the servers.

<br>

Version Fixed

8.1.8

Categories
Knowledge Support Support Categories Products exacqVision Integrations

Onvif mis-handle partial socket receive and could cause delay in connection

Description

This bug caused the Onvif configuration failed to handle a complete soap message when they are partially send. The end result is that there would be a long delay before the camera would be “connected”

<br>

Version Introduced

r34959 (dev build 5_1_9_34964)

<br>

Platform

All

<br>

Steps to reproduce

Use the Hitachi DI-CB320G(F8-48-97-9E-76-9E 10.16.11.47:8080 root/admin) for testing.

connect the camera with Onvif plugin.

<br>

Expected result

Camera connected with minimum delay.

<br>

Actual result

Camera in “connecting” state for long time(could be 10-20 minutes) and finally connected.

<br>

Work Around

none

<br>

Version Fixed

r103397 (dev build 8.1.8.103450)

<br>

Keywords

Onvif

Categories
Knowledge Support Support Categories Products exacqVision Integrations

Dahua/Illustra Essentials plugin failed to post NTP server address on the camera at startup.

Description

Dahua plugin which also supports Illustra Essentials failed to set the NTP server on the camera during initial connection time. By default if there is no override ntp server, the plugin should push the address of the server as NTP on the camera.

<br>

Version Introduced

r71495 (dev build 6.5.38.71503/RC build 6.6.0.71575)

<br>

Platform

All

<br>

Steps to reproduce

Factory default a Dahua/Illustra Essentials camera.

connect the camera to a server.

<br>

Expected result

NTP server on the camera should show either the server or override ntp server.

<br>

Actual result

NTP server on the camera stay with the defaulted ntp server(clock.isc.org)

When connect to UNA or Dynacolor Edge, the time could be off as well.

<br>

Work Around

manually override ntp server from client.

<br>

Version Fixed

r103423 (dev build 8.1.8.103450)

<br>

Keywords

Dahua

Categories
Knowledge Support Support Categories Products exacqVision Hardware

Product Security Advisory – CVE-2021-3156

Overview
Ubuntu recently announced security vulnerabilities that impact the exacqVision Network Video Recorder versions which use the Ubuntu Linux operating system. These affect a built-in Linux application called “Sudo” which controls the provisioning of super user (administrator) access to the operating system which, under certain circumstances, could be leveraged by an attacker to achieve unauthorized privilege escalation. Johnson Controls recommends that customers apply the Ubuntu security updates to all affected exacqVision product deployments.

Impact
Under specific circumstances, a local attacker could use this issue to obtain unintended super user access to the underlying Ubuntu operating system.

Affected Versions
exacqVision is available in both Windows and Linux versions. This issue affects all unpatched versions of the Ubuntu operating system used on Linux based Z-Series and A-Series and all Q-Series, G-Series, Legacy LC-Series, and Legacy ELP-Series exacqVision Network Video Recorders (NVR), as well as Linux based C-Series Workstations and all S-Series Storage Servers.

Mitigation
Install the latest security updates for the Ubuntu operating system. Users may contact exacqVision technical support for assistance with updating their operating system.
https://exacq.com/support/techsupport/

Initial Publication
April 29, 2021

Last Published
April 29, 2021

Resources
Cyber Solutions Website – https://www.johnsoncontrols.com/cyber-solutions/security-advisories
CVE-2021-3156 – NIST National Vulnerability Database (NVD) and MITRE CVE® List
ICSA-21-119-03 – CISA ICS-CERT Advisories
Ubuntu Security Notice 1 – https://ubuntu.com/security/notices/USN-4705-1
Ubuntu Security Notice 2 – https://ubuntu.com/security/notices/USN-4705-2


Ubuntu 18.04 and 16.04 Update Instructions

From the Ubuntu Desktop, click on “Applications > System Tools > Terminal”

Ensure your system can access the internet. Run the following command to update the available software from Ubuntu’s repository.

sudo apt upgrade

To update all packages (including kernel updates), run the following command:

sudo apt dist-upgrade

NOTE: Alternatively, to only update what’s necessary to address this vulnerability, run the following command:

sudo apt upgrade sudo

You will be prompted asking if you would like to continue, type ‘Y’ and hit ‘Enter’.

Categories
Knowledge Support Support Categories exacqVision Webservice Products

Video export downloads are slow

Description

Downloading exported video from the web service is extremely slow.

<br>

Version Introduced

7.9.24

<br>

Platform

All

Steps to reproduce

  1. Create a video export in the web client.
  2. Click the download link for the export.

<br>

Expected result

The file downloads at a reasonable rate (dependent on user’s bandwidth)

<br>

Actual result

The file downloads at 40k/s.

<br>

Work Around

  • Downloading the exported clip still works, just at a much slower rate, so a workaround isn’t strictly necessary.
  • Downgrade to an unaffected version of the web service.

<br>

Version Fixed

8.1.8

Categories
Knowledge Support Support Categories Products exacqVision Integrations

ePlayer failing to load dewarping libraries

Description

ePlayer is failing to load dewarp libraries

<br>

Version Introduced

7.9.20

<br>

Platform

Windows

<br>

Steps to reproduce

  1. Create an exe export from the client for any fisheye camera
  2. Open the exe export

<br>

Expected result

ePlayer should be able to dewarp the video

<br>

Actual result

ePlayer is not able to dewarp the video

<br>

Work Around

<br>

Version Fixed

8.1.6

<br>

Keywords

dewarp, export